80trust / 100
Capabilities Package Install Preflight
by vrsai in Security & trust
x402 APIPassing, checked 2 h ago
Check an exact npm or PyPI package version immediately before installation using current registry, vulnerability, malicious-package, withdrawal/deprecation, and verified provenance evidence. Returns ALLOW, REVIEW, BLOCK, or UNKNOWN with machine-readable reasons.
POST https://api.vrsai.tech/v1/capabilities/package_install_preflight
Last 30 days
All checks passedSome failedAll failedNot checked
- Uptime
- 100%
- Response time
- 673 ms typical, 673 ms slowest 5%
- Last check
- 2 h ago
- Next check
- any minute now
How to call it
# See the payment challenge (nothing is charged)
curl -i -X POST "https://api.vrsai.tech/v1/capabilities/package_install_preflight" \
-H "content-type: application/json" \
-d '{"purl":"pkg:npm/%40colors/[email protected]"}'import { wrapFetchWithPayment } from "@x402/fetch";
import { x402Client } from "@x402/core/client";
import { ExactEvmScheme } from "@x402/evm/exact/client";
import { privateKeyToAccount } from "viem/accounts";
const client = new x402Client().register(
"eip155:8453",
new ExactEvmScheme(privateKeyToAccount(process.env.AGENT_KEY)),
);
const pay = wrapFetchWithPayment(fetch, client);
// Not sure it's safe to pay? Preflight it first for $0.005:
// GET https://toolvet.app/api/v1/check?url=https%3A%2F%2Fapi.vrsai.tech%2Fv1%2Fcapabilities%2Fpackage_install_preflight
const res = await pay("https://api.vrsai.tech/v1/capabilities/package_install_preflight", {
method: "POST",
headers: { "content-type": "application/json" },
body: JSON.stringify({"purl":"pkg:npm/%40colors/[email protected]"}),
});
console.log(await res.json());Example input
{
"purl": "pkg:npm/%40colors/[email protected]"
}Example output
{
"decision": "ALLOW",
"evidence": [
{
"attempts": 1,
"latency_ms": 120,
"observed_at": "2026-08-26T00:00:00.000Z",
"source": "npm_registry",
"status": "OK"
},
{
"attempts": 1,
"latency_ms": 240,
"observed_at": "2026-08-26T00:00:00.000Z",
"source": "osv",
"status": "OK"
},
{
"attempts": 1,
"latency_ms": 90,
"observed_at": "2026-08-26T00:00:00.000Z",
"source": "deps_dev",
"status": "OK"
}
],
"input_fingerprint": "sha256:aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa",
"observations": {
"deps_dev": {
"advisory_ids": [],
"canonical_name": "@colors/colors",
"canonical_version": "1.5.0",
"licenses": [
"MIT"
]
},
"evidence_complete": true,
"provenance": {
"attestation_types": [],
"expected_repository_match": "NOT_REQUESTED",
"source_repositories": [],
"verified": false
},
"registry": {
"deprecated": false,
"distribution_hashes": [],
"exists": true,
"install_scripts": [],
"integrity": "sha512-fixture-integrity",
"repository_metadata": {
"url": "https://github.com/Marak/colors.js",
"verified": false
},
"yanked": "NONE",
"yanked_reasons": []
},
"vulnerabilities": {
"families": [],
"family_count": 0,
"malicious_package_signal": false,
"max_severity": "NONE",
"raw_record_count": 0
}
},
"observed_at": "2026-08-26T00:00:00.000Z",
"package": {
"ecosystem": "npm",
"name": "@colors/colors",
"purl": "pkg:npm/%40colors/[email protected]",
"version": "1.5.0"
},
"policy_version": "balanced-2026-08-26",
"reason_codes": [
"NO_BLOCKING_SIGNAL_OBSERVED"
],
"unknowns": []
}Security scan
- No findings. We scan names, descriptions and tool definitions for hidden instructions and other prompt-injection patterns.
Recent checks
| When | Result | HTTP | Time | Price |
|---|---|---|---|---|
| 2 h ago | Passed | 402 | 921 ms | $0.01 |
| 7 h ago | Passed | 402 | 673 ms | $0.01 |